> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/features-introduced-in-cortex-xdr-agent-7.6.md).

# Features Introduced in Cortex XDR Agent 7.6

The following topics describe the new features introduced in Cortex XDR agent 7.6 releases according to the supported agent operating systems.

* Features Introduced in Cortex XDR Agent 7.6

### Features Introduced in Cortex XDR Agent 7.6

* Cross-Platform Features
* Windows Features
* Mac Features
* Linux Features

#### Cross-Platform Features

The following features were added to Cortex XDR agents running on Windows, Mac, and Linux endpoints:

**Informative BTP Rule Alert Names and Descriptions**

(Requires a Cortex XDR Pro license)

Now Behavioral threat protection (BTP) alerts have been given unique and informative names and descriptions, to provide immediate clarity into the events without having to drill down into each alert:

* Alert names have been completely revised.
* New alert descriptions are now displayed alongside the existing descriptions. The module name remains Behavioral threat protection.

To start displaying the new BTP rule alert names and descriptions, you must enable this capability in your global agent settings. Once you update the settings, new alerts will include the changes while already existing alerts will remain unaffected.

If you have any Cortex XDR filters, starring policies, exclusion policies, scoring rules, log forwarding queries, or automation rules configured for XSOAR/3rd party SIEM, we advise you to update those to support the changes before activating the feature (for example, change the query to include the previous description that is still available in the new description, instead of searching for an exact match).

**Improved Security Content**

\*Starting with PTU 200 and later

To ensure your network is constantly protected against the latest and newest threats in the wild, the Cortex XDR research team will now start releasing more frequent content updates in-between major content versions. When you enable minor content updates, the Cortex XDR agent receives minor content updates, starting with the next content releases. Otherwise, if you do not wish to deploy minor content updates, your Cortex XDR agents will keep receiving content updates for major releases which usually occur on a weekly basis.

The content version numbering format remains XXX-YYYY, where XXX indicates the version and YYYY indicates the build number. To distinguish between major and minor releases, XXX is rounded up to the nearest ten for every major release, and incremented by one for a minor release. For example, 180-\<build\_num> and 190-\<build\_num> are major releases, and 181-\<build\_num>, 182-\<build\_num>, and 191-\<build\_num> are minor releases.

To enable this capability, you need to update the [Global Agent Settings](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md) for your tenant.

**Simplified Network Bandwidth Allocation for Security Content Updates**

For optimized performance and reduced bandwidth consumption, ensure you install new agents with the distribution package available for Windows Cortex XDR agents 7.3 and later. Otherwise, if you deploy the agent installer via SCCM, it is recommended to configure the bandwidth you allocate in your organization for the Palo Alto Networks content security updates. Cortex XDR now provides two recommendations, based on the number of agents you want to update (active or future gents), and according to the time frame during which you want the update to complete (within a day or a week). You can choose one of the recommended values or enter one of your own, between 20 - 10000 Mbps.

To adjust your settings, update the [Global Agent Settings](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md) for your tenant.

**Gradual Rollout for Automatic Agent Upgrades**

To better control the rollout of a new Cortex XDR agent release in your organization, during the first week only a single batch of agents is upgraded. After that, auto-upgrades continue to be deployed across your network in parallel batches as configured.

**Granular Exceptions for BTP Alerts**

You now have the option to create more granular Behavioral Threat Protection (BTP) exceptions for BTP alerts. These new additional BTP exceptions include the following Causality Group Owner (CGO) attributes:

* CGO hash value
* CGO signer entity (for Windows and Mac only)
* CGO process path—directory path of the CGO process.
* CGO command arguments—if a CGO process path is selected.

All previous BTP exception options are still available as usual.

#### Windows Features

The following features were added to Cortex XDR agents running on Windows endpoints:

**Supported Operating Systems**

To expand operating support, Cortex XDR agent supports Windows 11 and Windows Server 2022.

**New Persistence Tables**

(Requires a Forensics add-on license and a Cortex XDR agent 7.6 or later for Windows)

To expand your forensics investigation capabilities, Cortex XDR introduces the following new Persistence tables:

* Drivers
* Registry
* Scheduled Tasks
* Services
* Shim Databases
* Startup Folders
* WMI

**Permanently Delete Quarantined files**

To help you better manage malicious files which have been quarantined and avoid any potential mistake of restoring unwanted files, you can now permanently delete quarantined files on the endpoint from the File Quarantine Details page.

**Agent Uninstall Password Security Enhancements**

For an added layer of security when configuring the agent uninstall password, Cortex XDR now displays a password strength indicator to ensure that unauthorized users are not able to uninstall the Cortex XDR agent.

When defining the Uninstall Password in the Agent Configurations page and Agent Setting profile, the selected password must now obtain the Cortex XDR requirements enforced by password strength indicator.

**Malware Exception Profile Update Capabilities**

To expand your endpoint management capabilities during investigation, Cortex XDR now enables you to add a file path to the allow list of your endpoint Malware Security Profile directly from the right-click pivot menu of the:

* Alerts Table
* Events table of a process causality node
* XQL search result table

**New Comprehensive Forensics Add-On**

(Requires a Forensics add-on license and a Cortex XDR agent 7.4 or later)

Cortex XDR now offers a new add-on that enables you to perform comprehensive forensic investigations on your Windows endpoints.

With its deep data collection, the Forensics add-on enables you to find the source and scope of an attack, and determine what, if any, data was accessed. As an end-to-end solution, Cortex XDR Forensics helps you with every step of an incident response, from data collection, analysis, threat hunting, and remediation.

Using a host timeline, you can view user activity across multiple forensic artifacts in a single table. For a more detailed view, right-click on any row in the timeline for a complete listing of all fields for that item. The historical artifacts collected by the Forensics add-on can provide investigators with insight into Windows file access and process execution, even for files and executables that have been deleted from the host.

The triage functionality in the Forensics add-on collects detailed system information, including a full file listing for all of the connected drives, full event logs, and registry hives, so you can get a complete holistic picture of an endpoint.

You can perform a deep dive on a single endpoint or search for artifacts across all your endpoints from the Forensics workbench. For advanced detective work, you can use the XQL Search feature to query across all data, including endpoint, network, cloud and identity data.

You can access the Forensics add-on from the Add-Ons tab, under which the Host Insights add-on is also available (if licensed). Also, the configuration options that were previously labeled as Forensics are now labeled as Alerts Data.

**Enhancements to the Cortex XDR Host Firewall**

Now the Cortex XDR host firewall offers improved enforcement capabilities, better policy management, and greater visibility and troubleshooting capabilities into your network:

* Rules enforcement—The Cortex XDR host firewall rules are integrated with the Windows Security Center, and you can configure rules for all IP protocols, using multiple IP address notations, and more parameters.
* Policy management —Now the policy consists of rule groups that are reusable across all profiles, and there are default inbound and outbound rule groups provided by Palo Alto Networks. Additionally, you can import your rules directly into Cortex XDR.
* Visibility and troubleshooting—The Cortex XDR agent now reports aggregated host firewall enforcement events, and you can also view all single activities the agent performed in your network by retrieving a detailed log file. For Cortex XDR Pro customers, the host firewall events are now also queryable via XQL to enable data and network analysis.

For more details, refer to the [Cortex XDR administrator guide](/cortex-xdr-agent/9.2/introduction.md).

Cortex XDR 3.0 host firewall includes new features which are supported only with Cortex XDR agents 7.6 and later, such as multiple IP addresses, reporting mode, and more. For an older agent release, existing host firewall rules remain unaffected. However, if you create a rule from Cortex XDR 3.0, or edit an already existing rule that was created in an old Cortex XDR release and add one of these unsupported parameters, the agent could display unexpected behavior and the host firewall policy will be disabled on the endpoint.

**Network Packet Inspection Engine**

To address the threats surfacing with the growing remote workforce in your organization and the growing corporate network boundaries, the new Network Packet Inspection Engine provides coverage already at the network level. By analyzing the network packet data, the Cortex XDR agent can detect malicious behavior, and block or report it back to Cortex XDR.

The new engine leverages both Palo Alto Networks NGFW content rules, and new Cortex XDR content rules created by the Research Team.

To enable this capability, edit your [Malware Security Profile](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md) settings.

**Separate Actions for Files Unknown to WildFire and Files with Benign LC Score**

To better manage your anti-malware flow, you can now configure separate actions for files that are unknown to WildFire and files with Benign Low Confidence score. To adjust your settings, refer to the [Malware Security Profile](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md) settings.

**Configurable Device Control Enforcement Pop-Up Message**

You can now personalize the Cortex XDR notification pop-up on the endpoint when the user attempts to connect a USB device that is either blocked on the endpoint or allowed in read-only mode.

To enable this, refer to your [Agent Settings Profile](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md).

**Support for Azure-based Virtual Environments**

Support is now available for Cortex XDR agents running on Microsoft Azure-based VMs and virtual desktops (WVD or AVD).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/7.x/7.6-eol/features-introduced-in-cortex-xdr-agent-7.6.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
